Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service or other written agreement between bry3d llc ("BRY3D" or "Processor") and the customer identified in the applicable account or order form ("Customer" or "Controller"). This DPA governs BRY3D's processing of Customer Personal Data on Customer's behalf and is intended to satisfy Article 28 of the GDPR and corresponding requirements of other applicable data-protection laws.
1. Subject matter and roles
- The Customer is the controller of personal data it collects from its own prospects, customers, and staff and stores in the platform ("Customer Personal Data").
- BRY3D is the processor and processes Customer Personal Data only to provide the services described in the Terms: CRM, 3D viewers and configurators, enquiry forms, quoting, messaging, automations, AI assistance, and the customer portal.
- This DPA applies for as long as BRY3D processes Customer Personal Data.
2. Nature and purpose of processing
Subject matter: provision of the Services described in the Terms and the applicable order. Nature and purpose: collection, hosting, organization, storage, retrieval, consultation, use, transmission, display, automation, analysis, restriction, deletion, and other processing necessary to provide, secure, support, and maintain the Services configured by Customer. Duration: the term of the applicable Services and any limited period thereafter during which BRY3D processes Customer Personal Data in accordance with this DPA.
Categories of data subjects: the Customer's prospects and customers, website visitors interacting with the Customer's viewers, forms, or chat assistant, and the Customer's team members.
Categories of personal data: contact details (name, email, phone, address), company details, product configurations and quotes, order and job information, communications (email, chat, WhatsApp), documents and signatures, and technical data related to platform use. The platform is not intended for special categories of data (Art. 9 GDPR), and the Customer agrees not to store them in it.
3. Instructions
BRY3D shall process Customer Personal Data only on Customer's documented instructions, including the Terms, this DPA, the applicable order, Customer's configuration and use of the Services, and other written instructions acknowledged by BRY3D, unless processing is required by applicable law. If applicable law requires processing beyond Customer's instructions, BRY3D shall notify Customer before processing unless the law prohibits notice. BRY3D shall promptly inform Customer if, in BRY3D's opinion, an instruction violates applicable data-protection law.
4. Confidentiality and personnel
BRY3D ensures that persons authorized to process Customer Personal Data are bound by confidentiality obligations and access data only as needed for their role.
5. Security
BRY3D shall implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing. Current measures are described in the Security Statement. BRY3D may modify those measures provided that the modification does not materially reduce the overall security of the Services.
6. Sub-processors
Customer provides general written authorization for BRY3D to appoint the sub-processors listed below. BRY3D shall enter into a written agreement with each sub-processor imposing data-protection obligations no less protective than the obligations applicable to BRY3D under this DPA, to the extent relevant to the sub-processor's services. BRY3D remains responsible for the performance of each sub-processor as required by applicable law. BRY3D shall provide at least 14 days' prior notice of a new or replacement sub-processor. Customer may object during that period on reasonable, documented data-protection grounds. The parties shall cooperate in good faith to resolve the objection. If no commercially reasonable resolution is available, Customer may terminate the affected Services.
7. Current sub-processor list
| Sub-processor | Purpose | Safeguard for non-EEA processing |
|---|---|---|
| Supabase | Database, authentication, file storage | SCCs / DPF where applicable |
| Vercel | Application hosting, delivery, web analytics, and performance measurement | SCCs / DPF where applicable |
| Stripe | Payment and subscription processing | SCCs / DPF where applicable |
| Sentry | Error monitoring and diagnostics | SCCs / DPF where applicable |
| OpenAI (or the AI provider configured for the account) | AI assistant responses | SCCs / DPF where applicable |
| Meta Platforms (WhatsApp Business) | WhatsApp messaging and lead integrations, when connected by the Customer | SCCs / DPF where applicable |
| Calendar and Drive integrations, when connected by the Customer | SCCs / DPF where applicable | |
| n8n | Workflow automation between connected services | SCCs / DPF where applicable |
Integrations the Customer connects itself (for example its own email account, accounting tool, or a self-supplied AI key) act on the Customer's behalf and under the Customer's own agreement with that provider.
8. International transfers
Customer authorizes transfers of Customer Personal Data to the United States and other jurisdictions in which BRY3D or its authorized sub-processors operate. For restricted transfers subject to the GDPR, the parties incorporate the European Commission Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914, Module Two (Controller to Processor), with Customer as data exporter and BRY3D as data importer, unless another lawful transfer mechanism applies. For restricted transfers subject to the UK GDPR, the applicable UK International Data Transfer Addendum is incorporated. BRY3D shall implement supplementary measures where required by applicable law.
9. Assistance
- Data-subject requests: taking into account the nature of processing, BRY3D assists the Customer with appropriate technical and organizational measures (export, correction, and deletion tools in the platform; support on request) in fulfilling data-subject rights under Chapter III GDPR. Requests received directly by BRY3D that concern Customer Personal Data are forwarded to the Customer.
- Security, breach notification, DPIA: BRY3D assists the Customer with Art. 32–36 GDPR obligations, taking into account the information available to BRY3D.
10. Personal data breaches
BRY3D notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the information reasonably needed for the Customer's own notification obligations, and cooperates in investigating and mitigating the breach.
11. Deletion and return
During the term, Customer may export Customer Personal Data using available Service functionality. Upon termination or expiration of the Services, and at Customer's election where required by applicable law, BRY3D shall return or delete Customer Personal Data within 30 days, except to the extent retention is required by applicable law. Residual copies maintained in backups will be isolated from ordinary use and deleted in accordance with BRY3D's backup-retention cycle.
12. Audits
BRY3D shall make available information reasonably necessary to demonstrate compliance with Article 28 GDPR. Customer may conduct an audit, including an inspection, itself or through an independent auditor bound by confidentiality, no more than once in any 12-month period unless required by a supervisory authority or following a confirmed personal data breach. Customer shall provide at least 30 days' prior written notice, conduct the audit during normal business hours, avoid unreasonable disruption, and reimburse BRY3D's reasonable costs unless the audit identifies material noncompliance.
13. Liability and precedence
Liability under this DPA is governed by the limitation of liability in the Terms of Service. If this DPA conflicts with the Terms, this DPA prevails for data-protection matters. Translations are provided for convenience; the English version prevails.
14. Contact
Data-protection notices must be directed to admin@bry3d.com and to bry3d llc, 117 S Lexington Street, Suite 100, Harrisonville, Missouri 64701, United States.
This DPA may be accepted electronically as part of the Terms of Service. Electronic acceptance constitutes execution by the parties.